debug

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection because it ingests and processes untrusted external data.
  • Ingestion points: The skill reads application logs from directories like ./logs/ and /var/log/, and retrieves data from databases using sqlite3.
  • Boundary markers: There are no explicit instructions or delimiters provided to help the agent distinguish between its system instructions and the data retrieved from external logs or databases.
  • Capability inventory: The skill is capable of executing various shell commands for investigation, including ls, ps, lsof, git, and sqlite3.
  • Sanitization: The instructions do not include any steps for sanitizing, escaping, or filtering the content of logs or database records before the agent processes them.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:10 PM
Security Audit — agent-trust-hub — debug